bitspire/deploy/nixos/hardware/upboard.nix
Padreug bb2ad39628 feat(deploy): services.bitspire.nfc.enable — declare the reader per machine
pcscd was enabled in hardware/batm3.nix and hardware/upboard.nix, which
cannot express "is a reader fitted": upboard.nix is shared by sintra (HID
Global OMNIKEY 5022) and tejo (nothing fitted), so tejo inherited pcscd it
has no use for, while the douro — with its own hardware file — got none and
wedged on every boot.

Make it a machine capability instead. services.bitspire.nfc.enable owns
pcscd, the two polkit rules and the wedge-recovery unit, and hands the app
a BITSPIRE_NFC_ENABLED flag so it doesn't initialise nfc-pcsc at all on a
machine with no reader. Per-model truth lives in nfcReaderForModel in
flake.nix next to fiatCodeForModel and upgradeWindowForModel, since a
shared hardware file can't answer the question. batm3 and sintra are true;
douro and tejo flip to true when readers are fitted.

The flag goes through the unit's Environment rather than
/var/lib/bitspire/.env, because .env is only written when absent — a
machine provisioned months ago would never pick up a new value.
2026-09-29 22:49:59 +02:00

122 lines
4.5 KiB
Nix

# Tejo (UP Board / UP4000) Hardware Configuration
# Intel Atom/Celeron boards used in Lamassu Tejo ATM machines.
# Supports both UP Board and UP4000 variants — udev rules for both
# are included since they match different kernel paths and don't conflict.
#
# Serial port mapping:
# ttyJ4 = Printer (Nippon NP-2511D-2)
# ttyJ5 = Validator (iVizion, ID003 protocol)
# ttyJ7 = Dispenser (Fujitsu F53/F56)
{ config, lib, pkgs, ... }:
{
# Serial peripherals (validator/dispenser/printer modules + udev symlinks +
# console=tty0) are shared with the live ISO via ./upboard-serial.nix.
imports = [ ./upboard-serial.nix ];
boot = {
loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
timeout = 3;
};
initrd.availableKernelModules = [
"xhci_pci"
"ahci"
"usb_storage"
"sd_mod"
"sdhci_pci"
"sdhci-acpi" # UP Board sintra: eMMC controller is ACPI-enumerated, not PCI
"mmc_block" # creates /dev/mmcblk* block-device nodes
"i915"
];
# Force-load the eMMC stack in stage 1 so root-by-label resolves before
# the kernel hands off to switch_root. Without this, initramfs panics
# with "An error occurred in stage 1 of the boot process" because
# /dev/disk/by-label/nixos never materialises in time.
initrd.kernelModules = [
"sdhci-acpi"
"mmc_block"
];
kernelModules = [
"kvm-intel"
"i2c-dev"
"spi-dev"
# Serial modules (usbserial/ftdi_sio/cp210x) → ./upboard-serial.nix.
];
kernelParams = [
"i915.enable_psr=0"
# console=tty0 (keeps ttyS4 free for the F56) → ./upboard-serial.nix.
"quiet"
"splash"
];
};
# Disk layout: GPT with ESP + ext4 root (eMMC on UP Board).
# Labels match what make-disk-image.nix with partitionTableType="efi"
# produces — ESP for the FAT partition, nixos for the ext4 root. We
# previously expected `by-label/boot` here and had to manually
# `fatlabel` the partition post-flash; aligning the label avoids
# that hand-step on future re-flashes. (douro.nix already uses ESP.)
fileSystems."/" = {
device = "/dev/disk/by-label/nixos";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-label/ESP";
fsType = "vfat";
};
hardware = {
graphics = {
enable = true;
extraPackages = with pkgs; [
intel-media-driver
libva-vdpau-driver
libvdpau-va-gl
];
};
enableRedistributableFirmware = true;
cpu.intel.updateMicrocode = true;
};
powerManagement = {
enable = true;
cpuFreqGovernor = "performance";
};
# No pcscd here. This file is shared by sintra (HID Global OMNIKEY 5022
# fitted) and tejo (no reader), so the reader is declared per model via
# `nfcReaderForModel` in flake.nix → services.bitspire.nfc.enable.
# Disable suspend/hibernate for kiosk
systemd.targets = {
sleep.enable = false;
suspend.enable = false;
hibernate.enable = false;
hybrid-sleep.enable = false;
};
# Camera + LED/SPI peripherals. The serial rules (validator/dispenser/printer
# symlinks + permissions) are shared with the live ISO in ./upboard-serial.nix.
services.udev.extraRules = lib.mkAfter ''
# ── Camera devices ─────────────────────────────────────────────────
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-5", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-scan"
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-2", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-scan"
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-6", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-front"
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-3", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-front"
# ── LED SPI / peripherals ──────────────────────────────────────────
KERNEL=="spidev1.0", SYMLINK+="ledspi"
KERNEL=="spidev2.0", SYMLINK+="ledspi"
SUBSYSTEM=="spidev", GROUP="spi", MODE="0660"
SUBSYSTEM=="i2c-dev", GROUP="i2c", MODE="0660"
SUBSYSTEM=="leds", KERNEL=="upboard:*", ACTION=="add|change", RUN+="${pkgs.findutils}/bin/find /sys$devpath -type f -exec ${pkgs.coreutils}/bin/chmod g+u {} + -exec ${pkgs.coreutils}/bin/chown :leds {} +"
'';
}